PULSE NAME
CrySome RAT : An Advanced Persistent .NET Remote Access Trojan
WHITE AlienVault 2026-03-31 Modified: 2026-03-31
8
IOCs
LOW VOLUME
CrySome is a sophisticated .NET-based remote access trojan designed for persistent command-and-control operations. It features advanced persistence mechanisms, including recovery partition abuse and offline registry modification, allowing it to survive system resets. The malware incorporates an aggressive defense evasion module, disabling security products and blocking updates. Key capabilities include command execution, file operations, surveillance, credential theft, and hidden virtual desktop control. CrySome's modular architecture and structured packet-based protocol enable a wide range of remote operations. Its emphasis on stealth, resilience, and comprehensive system control makes it a significant threat for long-term covert access to compromised environments.
Indicators of Compromise (3 / 8 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 a89158fe7d762dca8f136498a4120e3597933cab 2026-03-31
FileHash-SHA1 b4070db8f451731ab768a530f6738cc1800a300b 2026-03-31
FileHash-SHA1 61d065d0afd03bac6a42cb39d48115f66b9fb3ff 2026-03-31